CRITICAL · 9.8

CVE-2019-13990

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Vulnerability Description

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SoftwareagQuartz< 2.3.2
OracleApache Batik Mapviewer12.2.0.1
OracleBanking Enterprise Originations2.7.0
OracleBanking Enterprise Product Manufacturing2.7.0
OracleBanking Payments>= 14.1.0, <= 14.4.0
OracleCommunications Ip Service Activator7.3.0
OracleCommunications Session Route Manager>= 8.2.0, <= 8.2.2
OracleCustomer Management And Segmentation Foundation18.0
OracleDocumaker>= 12.6.0, <= 12.6.4
OracleEnterprise Manager Base Platform13.2.1.0
OracleEnterprise Manager Ops Center12.4.0.0
OracleFlexcube Investor Servicing12.1.0
OracleFlexcube Private Banking12.0.0
OracleFusion Middleware Mapviewer12.2.1.3.0
OracleGoogle Guava Mapviewer12.2.0.1
OracleHyperion Infrastructure Technology11.1.2.4
OracleJd Edwards Enterpriseone Orchestrator<= 9.2.5.3
OraclePrimavera Unifier>= 17.7, <= 17.12
OracleRetail Back Office14.1
OracleRetail Central Office14.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-13990?

CVE-2019-13990 is a vulnerability with a CVSS score of 9.8 (CRITICAL). initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

How severe is CVE-2019-13990?

CVE-2019-13990 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-13990?

Check the references section above for vendor advisories and patch information. Affected products include: Softwareag Quartz, Oracle Apache Batik Mapviewer, Oracle Banking Enterprise Originations, Oracle Banking Enterprise Product Manufacturing, Oracle Banking Payments.